← Back to browse · API

CVE-2024-27130

Severity
HIGH
CVSS
7.2
EPSS
0.38054
Risk score
42.12
CISA KEV
No
PoC
No
Published
2024-05-21
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-24380, GHSA-C3MM-2W2H-VX43
Products
QNAP Systems Inc.:QTS 5.1.x <5.1.7.2770 build 20240520, QNAP Systems Inc.:QuTS hero h5.1.x <h5.1.7.2770 build 20240520
Sources
euvd EUVD-2024-24380

Description

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later

References